SecondFi Unveils Three-Stage Plan to Refund ADA Owners After $2.5 Million Hack
The Cardano wallet SecondFi has announced a plan to refund affected users after being hacked in June, when $2.5 million worth of ADA was stolen by the Lazarus Group.
The attack exploited a vulnerability in the Android version of the app and allowed hackers to cryptographically derive users' private keys. However, the team managed to save 129 million ADA by transferring funds to custodial storage.
To return the remaining assets, SecondFi is working with Input Output Group and the Cardano Foundation to launch a Web3 compensation tool based on zero-knowledge proofs. The project has divided the recovery process into three stages: claims submission, migration tool, and ZK refund portal.
The first stage allows affected users to submit claims through a simplified ticket system, which is already available. In mid-August, a migration tool will automatically withdraw assets without revealing seed phrases or private keys. The ZK refund portal, set to launch in early September, will use zero-knowledge proofs to verify ownership and facilitate compensation.
The team has warned users about phishing scams targeting SecondFi's closure, advising them not to share sensitive information with anyone claiming to be customer support representatives.